In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like --new-pr, --fro,-pr, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed in EasyBuild v4.1.2, and in the master+ develop branches of the easybuild-framework repository.
The product writes sensitive information to a log file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Easybuild | Easybuild_project | * | 4.1.2 (excluding) |